CVE-2025-1638
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-1638 is a critical vulnerability affecting the Alloggio Membership plugin for WordPress. The issue lies in the plugin's failure to validate user identities during the Facebook and Google login processes, specifically within the alloggio_membership_init_rest_api_facebook_login and alloggio_membership_init_rest_api_google_login functions. This flaw allows unauthenticated attackers to bypass authentication and log in as any user, including administrators, without requiring a password. This vulnerability poses a significant risk for WordPress sites using the Alloggio Membership plugin and is advised to be addressed immediately by updating to the latest version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Alloggio Membership Plugin
Affected Vendors
- WordPress